Improper access control in OpenClaw - CVE-2026-27004
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in session tools when handling session-targeting operations in shared-agent multi-user deployments. A remote user can access broader peer session data to disclose sensitive information.
Exploitation is relevant in shared-agent multi-user environments where peers are not equally trusted.